CVE-2026-3241
Received
Received - Intake
Stored XSS in Concrete CMS Legacy Form Allows Persistent Injection
Publication date: 2026-03-04
Last updated on: 2026-03-04
Assigner: ConcreteCMS
Description
Description
In Concrete CMS below version 9.4.8, aΒ stored cross-site scripting (XSS) vulnerability exists in the "Legacy Form" block. An authenticated user with permissions to create or edit forms (e.g., a rogue administrator) can inject a persistent JavaScript payload into the options of a multiple-choice question (Checkbox List, Radio Buttons, or Select Box). This payload is then executed in the browser of any user who views the page containing the form.Β The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 4.8 with vectorΒ CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. ThanksΒ M3dium for reporting.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| concretecms | concrete_cms | to 9.4.8 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |